2026 CVE Vulnerabilities
65,972 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97863 | MEDIUM | 6.3 | 0.3% | Sep 25, 2026 | The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to ... |
| CVE-2026-92573 | MEDIUM | 6.5 | — | Sep 25, 2026 | Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message d... |
| CVE-2026-92564 | HIGH | 7.5 | 0.2% | Sep 25, 2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of... |
| CVE-2026-92560 | HIGH | 7.5 | — | Sep 25, 2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential... |
| CVE-2026-92550 | HIGH | 7.5 | — | Sep 25, 2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential... |
| CVE-2026-88848 | MEDIUM | 4.2 | — | Sep 25, 2026 | The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is c... |
| CVE-2026-86837 | MEDIUM | 5.3 | — | Sep 25, 2026 | The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored deta... |
| CVE-2026-80514 | MEDIUM | 5.3 | — | Sep 25, 2026 | The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address heade... |
| CVE-2026-6088 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6087 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6086 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6085 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6084 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6083 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6082 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-96752 | HIGH | 7.2 | — | Sep 25, 2026 | The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys... |
| CVE-2026-96568 | HIGH | 7.2 | — | Sep 25, 2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_n... |
| CVE-2026-96448 | MEDIUM | 6.6 | 0.2% | Sep 25, 2026 | A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management ... |
| CVE-2026-95866 | HIGH | 7.2 | — | Sep 25, 2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2026-95864 | HIGH | 7.2 | — | Sep 25, 2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all ... |
| CVE-2026-94573 | HIGH | 7.2 | — | Sep 25, 2026 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater F... |
| CVE-2026-93901 | HIGH | 7.3 | — | Sep 25, 2026 | The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, ... |
| CVE-2026-93747 | MEDIUM | 6.4 | — | Sep 25, 2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in v... |
| CVE-2026-93656 | MEDIUM | 6.4 | — | Sep 25, 2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2026-93654 | HIGH | 7.2 | — | Sep 25, 2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now